Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

China-Linked Storm-1175 Exploits Zero-Days to Rapidly Deploy Medusa Ransomware

The Hacker News by The Hacker News
April 7, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananApr 07, 2026Vulnerability / Threat Intelligence

A China-based threat actor known for deploying Medusa ransomware has been linked to the weaponization of a combination of zero-day and N-day vulnerabilities to orchestrate “high-velocity” attacks and break into susceptible internet-facing systems.

“The threat actor’s high operational tempo and proficiency in identifying exposed perimeter assets have proven successful, with recent intrusions heavily impacting healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, the United Kingdom, and the United States,” the Microsoft Threat Intelligence team said.

Attacks mounted by Storm-1175 have also leveraged zero-day exploits, in some cases, before they have been publicly disclosed, as well as recently disclosed vulnerabilities to obtain initial access. Select incidents have involved the threat actor chaining together multiple exploits (e.g., OWASSRF) for post-compromise activity.

Upon gaining a foothold, the financially motivated cybercriminal actor swiftly moves to exfiltrate data and deploy Medusa ransomware within a span of a few days, or, in select incidents, within 24 hours.

To aid in these efforts, the group creates persistence by creating new user accounts, deploying web shells or legitimate remote monitoring and management (RMM) software for lateral movement, conducting credential theft, and interfering with the normal functioning of security solutions, before dropping the ransomware.

Since 2023, Storm-1175 has been linked to the exploitation of more than 16 vulnerabilities –

Both CVE-2025-10035 and CVE-2026-23760 are said to have been exploited as zero-days prior to them being publicly disclosed.As of late 2024, the hacking crew has exhibited a flair for targeting Linux systems, including exploiting vulnerable Oracle WebLogic instances across several organizations. However, the exact vulnerability that was being weaponized in these attacks remains unknown.

“Storm-1175 rotates exploits quickly during the time between disclosure and patch availability or adoption, taking advantage of the period where many organizations remain unprotected,” Microsoft said.

Some of the notable tactics observed in these attacks are as follows –

  • Using living-off-the-land binaries (LOLBins), including PowerShell and PsExec, along with Impacket for lateral movement.
  • Relying on PDQ Deployer for both lateral movement and payload delivery, including Medusa ransomware, across the network.
  • Modifying Windows Firewall policies to enable Remote Desktop Protocol (RDP) and deliver malicious payloads to other devices.
  • Carrying out credential dumping using Impacket and Mimikatz.
  • Configuring Microsoft Defender Antivirus exclusions to prevent it from blocking ransomware payloads.
  • Leveraging Bandizip and Rclone for data collection and exfiltration, respectively.

The bigger implication here is that RMM tools like AnyDesk, Atera, MeshAgent, ConnectWise ScreenConnect, or SimpleHelp are becoming dual-use infrastructure for covert operations, as they allow threat actors to blend malicious traffic into trusted, encrypted platforms and reduce the likelihood of detection.



Source link

The Hacker News

The Hacker News

Next Post
Etteplan strengthens its global footprint in fiber routing solutions as demand for high-density optical fiber flex circuits grows

Etteplan strengthens its global footprint in fiber routing solutions as demand for high-density optical fiber flex circuits grows

Recommended.

NetActuate Enhances Mumbai Cloud Platform with ONE Capabilities

NetActuate Enhances Mumbai Cloud Platform with ONE Capabilities

February 16, 2026
Inside the trend of tech ‘spinouts’ solving real-world problems | Computer Weekly

Inside the trend of tech ‘spinouts’ solving real-world problems | Computer Weekly

January 23, 2026

Trending.

Half of Google’s software development now AI-generated | Computer Weekly

Half of Google’s software development now AI-generated | Computer Weekly

February 5, 2026
Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

Ghost Campaign Uses 7 npm Packages to Steal Crypto Wallets and Credentials

March 24, 2026
How Ceros Gives Security Teams Visibility and Control in Claude Code

How Ceros Gives Security Teams Visibility and Control in Claude Code

March 19, 2026
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers

April 3, 2026
Super Micro Computer Issues Statement on Action by U.S. Attorney’s Office

Super Micro Computer Issues Statement on Action by U.S. Attorney’s Office

March 19, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio